Attack Surface Management for Small Business: What's Exposed to the Internet Right Now (2026)

Ulises Paiz

Ulises Paiz, Founder of Ghosxt, has 10+ years in IT infrastructure and cybersecurity, deep DoD infrastructure experience, and 9 certifications including CySA+, Security+, and AZ-104. Before founding Ghosxt, he served as a Senior Solutions Consultant for the DoD and built security programs for 40+ Central Coast businesses. More about Ulises →

Ask a small business owner what's exposed to the internet and most will point to the website. That's rarely the full picture. Between an old marketing subdomain still pointing at a decommissioned server, a VPN portal set up for a project that wrapped up two years ago, and a cloud storage login that belonged to someone who left the company last spring, the real answer is usually a list nobody has ever written down. Attack surface management is the practice of writing that list, from the outside, the same way an attacker would build it, and then actually doing something about what's on it.

Why your attack surface is bigger than you think

Nobody sets out to expose more than they mean to. It happens the same way clutter accumulates anywhere: one reasonable decision at a time, none of them tracked against the others. A developer spins up a quick staging site to show a client and forgets to take it down. A vendor gets temporary remote access for a project and the account never gets revoked. A DNS record for an old email marketing tool keeps pointing somewhere that hasn't been renewed in years. None of these felt risky when they happened. Stacked together, they're a set of doors nobody remembers unlocking.

  • Forgotten subdomains and DNS records. Marketing campaigns, product demos, and old vendor integrations leave subdomains resolving long after anyone uses them, some pointing at infrastructure that's been retired and can be hijacked outright.
  • Orphaned accounts and logins. Former employees, past contractors, and vendors whose engagement ended months ago often keep working access to cloud storage, email, or admin panels because offboarding covers the obvious systems and misses the rest.
  • Shadow IT. Tools an employee signed up for with a company email, outside of anything IT approved or even knows about, each with its own login and its own exposure. Our shadow IT post covers how this creeps in.
  • Exposed remote access. A VPN appliance, an RDP port left open for a one-time fix, or an admin panel that was supposed to be temporary, all reachable from anywhere, indefinitely, until someone checks.
  • Cloud storage with the wrong sharing default. A folder shared "anyone with the link" for a single external review that never gets set back to private.

How small businesses actually find out what's exposed

The starting point is discovery from the outside looking in, not a walk-through of what IT thinks is running. Domain and subdomain enumeration maps every hostname tied to the business, including the ones nobody remembers registering. Port and service scanning shows what's actually reachable on the open internet right now, not what a diagram from two years ago says should be. Cloud account reviews catch former employees and vendors who still have working logins long after their reason for having one ended. And a breach-data check tells you whether credentials tied to company email addresses are already circulating from an unrelated third-party breach, which matters because reused passwords turn someone else's incident into yours; our dark web monitoring post goes deeper on that piece specifically.

This is a different exercise from a penetration test, and the two get confused often enough that it's worth being precise about it. A pentest asks "how far could an attacker get into the systems we already know about?" Attack surface management asks the question that comes first: "what do we actually have exposed, including the parts nobody remembers?" Skipping straight to a pentest without doing the discovery first means testing against an incomplete map, and the thing that gets you breached is rarely the system everyone was already watching.

Turning visibility into a shrinking attack surface

Finding the list is the easy half. The harder, more valuable half is deciding what to do with each item on it, and most of it is cleanup rather than new engineering. Anything genuinely unused gets decommissioned outright: the DNS record gets deleted, the server gets shut down, the account gets revoked. Anything still needed but overexposed gets restricted, an admin panel that has to exist doesn't have to be reachable from any IP address on earth; putting it behind a VPN or an allowlist removes it from the public attack surface without removing the functionality. Everything that remains gets MFA, current patches, and a place on the inventory so it doesn't quietly become "forgotten" again in six months.

The part that actually holds up over time is treating this as a cadence, not a project with an end date. New exposures appear constantly, a landing page for a seasonal promotion, a demo environment for evaluating new software, a contractor's temporary access, so a scan done once and filed away is stale within weeks. Continuous or monthly discovery, paired with the offboarding discipline covered in our employee offboarding post, is what keeps the list accurate instead of aspirational.

Where this fits

We run attack surface discovery as part of security assessments for small businesses across Salinas, Monterey, Santa Cruz, Watsonville, and San Jose, and the rest of the Central Coast, so "here's what we're exposed to" is a real list, not a guess.

FAQs about attack surface management for small business

What is attack surface management?

Attack surface management (ASM) is the ongoing process of discovering, inventorying, and monitoring every asset a business exposes to the internet, domains, subdomains, cloud logins, VPN portals, servers, and APIs, from an outside attacker's point of view, so unknown or forgotten exposures get found and closed before someone else finds them first.

How is attack surface management different from a penetration test?

A penetration test is a point-in-time, hands-on attempt to break into systems you already know about, testing how deep an attacker could get. Attack surface management runs continuously and answers a different question first: what do we actually have exposed to the internet, including assets nobody remembered were still running. ASM finds the target list; a pentest tests how well it holds up.

How often should a small business scan its attack surface?

Attack surface discovery should run continuously or at minimum monthly, not once a year. New assets appear constantly, a marketing team spins up a landing page, a vendor demo leaves a subdomain live, a departing employee's cloud account never gets removed, and an annual review misses everything that showed up and disappeared in between.

Can a small business reduce its attack surface without hiring a security team?

Yes. Most of the reduction is decommissioning and cleanup work, not advanced engineering: retiring unused subdomains and DNS records, closing accounts for former employees and vendors, taking test and staging sites offline or off the public internet, and turning on MFA everywhere that remains. A managed IT provider can run the discovery and handle the cleanup on a schedule.

Not sure what your business actually looks like from the outside?

30 minutes with an engineer with DoD infrastructure experience. We'll map what's exposed, what's forgotten, and what closing the gaps actually costs, no scanner install, no obligation.

Book your free security assessment
Call (831) 204-0501 Book free assessment